Microsoft Word flaw may allow file theft
It's worst on MS Office 97, but newer versions are vulnerable as well.
Here's a Patch 😀
It's worst on MS Office 97, but newer versions are vulnerable as well.
Here's a Patch 😀
Originally posted by: Codewiz
Ummmmmmmmm, what is the big deal over this security hole???? I could just as easily walk up to your computer and take your damn files. It would take a good amount of inside info to steal files using this method. I think personally you would have a better chance at infecting someone with a virus to steal their files.........
Ummmmmmmmm, what is the big deal over this security hole???? I could just as easily walk up to your computer and take your damn files. It would take a good amount of inside info to steal files using this method. I think personally you would have a better chance at infecting someone with a virus to steal their files.........
A GNU/Linux worm exploiting a bug in OpenSSL spreads through vulnerable Apache web servers, according to Symantec. The worm, which was first reported in Europe, targets several popular Linux distributions. See also the SecurityFocus vulnerability listing for the OpenSSL bug." sionide also writes: "Netcraft recently published a report which explains that a large portion of Apache systems are still unpatched (halfway down). To protect yourself please upgrade to OpenSSL 0.9.6g."
OMG DROP LINUX/APACHE/SSL NOW.....IT HAS HUGE GAPING SECURITY HOLES.
I just think that every is quick to jump on MS about their security holes and not a mention of security holes that are found in other products. I just feel if you are going to jump on MS then jump on other products too.
Originally posted by: Codewiz
Yeah, I am happy to make a big deal out of MS not fixing Word 97 because that is just BS. Shame on MS.
IIS isn't leading the pack on web servers. Apache is 🙂 So that isn't very valid.
I have never been effected by any security problems with MS products and I hope I never am. I just think some things get blown out of proportion but sometimes the security issues are big deals especially when MS doesn't offer a fix in a timely manner.
Originally posted by: Codewiz
A GNU/Linux worm exploiting a bug in OpenSSL spreads through vulnerable Apache web servers, according to Symantec. The worm, which was first reported in Europe, targets several popular Linux distributions. See also the SecurityFocus vulnerability listing for the OpenSSL bug." sionide also writes: "Netcraft recently published a report which explains that a large portion of Apache systems are still unpatched (halfway down). To protect yourself please upgrade to OpenSSL 0.9.6g."
OMG DROP LINUX/APACHE/SSL NOW.....IT HAS HUGE GAPING SECURITY HOLES.
My point is the fact that every OS and/or product is going to have security holes.
As a matter of fact most companies are NOT strict who walks in their building. There was a story about a year ago from a magazine where a person walked in to a company and acted like he worked there it. It took the company two weeks to figure it out he didn't work there. Everyone assumed he was just a new employee.
Have you ever been into MOST environments. I had to HASSLE people to not write their password down on a piece of paper on their desk. These are the same stupid people that would click yes to a VBS. So the people that would have their DOCs stolen via a VBS are the same ones I could walk up and steal their documents.
Anyone that has documents that are private should exercise their own caution when opening other people's documents. I never CLICK ok unless I know what is happening.
Stupid users are the problem....
Prior to this warning, did you even consider that editing somebody else's Word document was a security risk?
Wouldn't happen here. You don't get in without a badge, and they occasionally turn on the retinal scanners.
Originally posted by: Codewiz
Prior to this warning, did you even consider that editing somebody else's Word document was a security risk?
HELL FVCKING YES I HAVE. Ever heard of a macro virus?????? I would have NEVER run a VBS in a word document until I verified the intent of it. You are just stupid if you do. I would bet that you are the same person that would just open an attachment from a person in email because you know them. It is called caution.
Like I have said. The bug alone cannot hurt you. It takes other factors to be effective. The other factors take stupidity to be part of the equation.
Wouldn't happen here. You don't get in without a badge, and they occasionally turn on the retinal scanners.
UMMMMM most companies are not like this.
Originally posted by: Codewiz
Stupid users are the problem......
EDIT: I also think that MS has more than their fair share of security holes BUT they also have a lot of products. Name one company that produces this much code and has less security holes? I just think that every is quick to jump on MS about their security holes and not a mention of security holes that are found in other products. I just feel if you are going to jump on MS then jump on other products too. I also think it is sh*tty that MS is not going to fix this problem on Word 97.
In case you were a bit slow to notice, these "security flaws" seem to be ENDEMIC to ALL MS SOFTWARE. Other software has bugs, sure, including security bugs, but at least they are designed with some security in mind.
It's basically the difference between a cold being transmitted between a few people, and the plague sweeping through your neighborhood and killing everyone.
Or maybe more accurately, eating at a certain local restaraunt, that is known to be relatively clean, but occasionally something slips through, and someone who eats there gets sick, versus eating at a place where they don't ever even clean the grill, much less the silverware. Sure, the place is cheap, and has lots of neon signs pointing to that place... but if everyone gets sick... why do people keep eating there???
Yeah, that is a good analogy for MS software... if people keep getting their systems cracked/hacked/broken into, why the heck do they still use MS software? Sure, MS should be responsible for the security of their software - even if they aren't taking responsibility for it - but at some point, the owners of each individual system, should be responsible for their own data, and to knowingly continue to use MS software, and to continuously put their data at risk because of that poor administrative decision ... personally, I see A LOT of shareholder lawsuits, among others, in the future, after the next huge thing to exploit security holes in MS software comes out. As it is, many places are afraid to use IIS anymore, and I don't blame them. Would you hire a security company, to protect your property at night, if you knew that out of places that had hired that company in the past, over fifty percent of them had been broken into? And if you worked for a company, and were responsible for the eventual outcome of that decision to hire that security company?
Microsoft. Just say No.